news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans Schneider Electric EcoStruxure (08 septembre 2026)

Medium
Summary

Schneider Electric’s EcoStruxure systems are vulnerable to remote code execution and server-side request forgery attacks. These flaws could allow attackers to gain control of affected devices and potentially compromise sensitive data. The vulnerabilities have been identified and a security advisory has been released by Schneider Electric.

Schneider Electric has announced multiple security vulnerabilities within its EcoStruxure system. These vulnerabilities allow for remote code execution and server-side request forgery attacks. The EcoStruxure IT Data Center Expert is affected by these flaws, specifically versions prior to 9.1.2. The security advisory highlights the risk of an attacker gaining remote control of devices and potentially accessing sensitive information. Schneider Electric has released a security advisory (SEVD-2026-251-01) and provided links to the advisory document and CVE records.

CVE-2026-19233 and CVE-2026-8044 are the identified CVEs associated with these vulnerabilities. The security advisory directs users to download and install the appropriate security updates to mitigate the risks.

Read the full article at CERT-FR